Paypal phishing w/o hosted HTML files

It is the first time I can see a phishing that doesn’t have a website to store the website !

This email came as a self sustained phishing solution.


My company offers consulting on how to prepare for TISAX, ISO27001, NIS2, CSMS and SOC2 audits.
Get in touch with us here: https://www.endpoint-cybersecurity.com/contact/

It is written in HTML and JS and it has a FORM whos action is POST to a website which saves the data.

The submit button goes to http://www.webformdesigner.net/wfd_f2.php?id=QjfYrttfx8.

The website is not randomly chosen 😉

Web Form Designer is a legitimate company that produces such emails …

Have a look here:  http://www.webformdesigner.net/

The mail doesn’t have anything special in it. It asks for the usual stuff : CC number, PIN (never asked by a legitimate company or webshop) , etc.


© Copyright 2006 Sorin Mustaca, All rights Reserved. Written For: Sorin Mustaca - Security & Technology


Want to work with me on this topic?
Check Endpoint Cybersecurity to see the consulting services we offer.